Cassianetworks develops a focused product line of Bluetooth access controllers and related firmware, including models such as the XC1000 and XC2000, that manage wireless device connectivity in enterprise environments. Its disclosed vulnerabilities cluster around web-application and authentication boundaries—cross-site request forgery, improper authentication, path traversal, command injection, and incorrect permission assignment—reflecting the management interface and device-access control surfaces that characterize this class of networked appliance. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cassianetworks over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31446CRITICAL In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and exe | Jan 10, 2024 | 9.8 | 73 | NO | YES |
CVE-2023-35793HIGH An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks. | Sep 27, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-22685HIGH An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controller prior to 2.0.1. | Oct 14, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-35794HIGH An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is | Oct 27, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-31445MEDIUM Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumer | May 11, 2023 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cassianetworks.
Media articles that mention a CVE ID that affects a product developed by Cassianetworks — matched by CVE ID, not by vendor name.